Stored Cross-Site Scripting Vulnerability in LimeSurvey by LimeSurvey GmbH
CVE-2022-48010

5.4MEDIUM

Key Information:

Vendor

Limesurvey

Vendor
CVE Published:
27 January 2023

What is CVE-2022-48010?

LimeSurvey v5.4.15 is vulnerable to a stored cross-site scripting (XSS) attack via the /index.php/surveyAdministration/rendersidemenulink?subaction=surveytexts component. Attackers can exploit this vulnerability by injecting malicious scripts through the Description or Welcome-message fields, enabling them to execute arbitrary web scripts or HTML. Although the vendor claims that exploiting this vulnerability requires Superadministrator privileges, which are inherently capable of customizing surveys using JavaScript, it remains a notable security concern that could lead to data exposure or manipulation.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.